Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨£»£»£»£»£»£»£»£»ESETÅû¶LazarusÕë¶Ôº«¹ú¹©¸øÁ´µÄй¥»÷»î¶¯

°ä²¼¹¦·ò 2020-11-17
1.Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨


1.jpg


Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨ÏÔʾ £¬ £¬£¬£¬£¬63£¥µÄÊÜ·ÃÕ߳Ƽ¼ÊõÖÎÀí±äµÃÔ½À´Ô½ÄÑÌâ £¬ £¬£¬£¬£¬ÆóÒµÔÚÈí¼þ¡¢Ó²¼þ¡¢SaaSºÍÔÆÉϵļ¼ÊõÖ§³öÈ«ÃæÔö³¤¡£¡£¡£¡£¡£87£¥µÄIT¸¨µ¼Õß°µÊ¾ £¬ £¬£¬£¬£¬´ÓǰһÄêÖÐËûÃÇÒѾ­¹ýMicrosoft¡¢IBM¡¢Oracle¡¢AdobeºÍSAPµÈÈí¼þ¹©¸øÉ̵ÄÉó¼Æ £¬ £¬£¬£¬£¬Ö»ÓÐ51£¥µÄÈ˲»°²ÏÂÒ»ÄêµÄÉ󼯡£¡£¡£¡£¡£´Ë±í £¬ £¬£¬£¬£¬×³´óµÄ¼¼Êõµý±¨Ê¹IT¸¨µ¼ÕßÄܸüÓÐЧµØ½â¾öËûÃǵÄÊ×Òª¹¤×÷ £¬ £¬£¬£¬£¬µ«Ö»ÓÐ14%µÄIT¸¨µ¼Õß´ïµ½Á˳ÉÊì¼¼ÊõÖÇÄܵij߶ȡ£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.snowsoftware.com/company/news/cios-face-competing-and-complex-priorities-2021-finds-new-snow-software-report


2.kaspersky°ä²¼Snake¶Ô¹¤¿ØÐÐÒµµÄ¹¥»÷·ÖÎö»ã±¨


2.jpg


kaspersky ICS CERT°ä²¼ÁËÓйØSnake¶Ô¹¤¿ØÐÐÒµµÄ¹¥»÷·ÖÎö»ã±¨¡£¡£¡£¡£¡£»ã±¨ÖØÒª·¢ÏÖÔ̺¬ £¬ £¬£¬£¬£¬¸Ã¶ñÒâÈí¼þʹÓÃnmon.batÎļþ½øÐÐÆô¶¯£»£»£»£»£»£»£»£»Ëùʶ´ËÍâËùÓÐSnakeÑù±¾Ö®¼äµÄÎ¨Ò»Çø±ðÊÇ´úÂëÖÐǶÈëµÄÓòÃûºÍIPµØÖ·£»£»£»£»£»£»£»£»Ö»Óе±Ç¶ÈëÔÚ¶ñÒâÈí¼þ´úÂëÖеÄIPµØÖ·Óë´ÓͬÑùǶÈëÔÚ¶ñÒâÈí¼þ´úÂëÖеÄÓòÃû½âÎöµÄIPµØÖ·ÏàÆ¥Åäʱ £¬ £¬£¬£¬£¬¶ñÒâÈí¼þ²Å»á¼ÓÃÜÊý¾Ý£»£»£»£»£»£»£»£»¶ÔÓÚÿ´Î¹¥»÷ £¬ £¬£¬£¬£¬Ç¶ÈëÔÚ¶ñÒâÈí¼þ´úÂëÖеÄIPµØÖ·ºÍÓòÃû×éºÏ¶¼ÊÇΨһµÄ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://ics-cert.kaspersky.com/alerts/2020/06/17/targeted-attacks-on-industrial-companies-using-snake-ransomware/


3.Value DeFiÔâµ½Flash loan¹¥»÷ £¬ £¬£¬£¬£¬Ôì³ÉÔ¼600ÍòÃÀÔªËðʧ


3.png


È¥ÖÐÐÄ»¯½ðÈÚ£¨DeFi£©ºÍ̸Value DeFi³ÆÆäÉÏÖÜÁùÔâµ½ÁËFlash loan¹¥»÷ £¬ £¬£¬£¬£¬Ôì³ÉÔ¼600ÍòÃÀÔªËðʧ¡£¡£¡£¡£¡£¹¥»÷ÕßÕë¶Ô¸Ã¹«Ë¾MultiStables½ð¿â½øÐÐÁ˸´ÔÓµÄFlash loan¹¥»÷¡£¡£¡£¡£¡£Flash loan´û¿îÔÊÐíÓû§ÔÚûÓеÖѺµÄÇé¿öϽèÈë×ʽ𠣬 £¬£¬£¬£¬ÓÉÓÚ´û·½Ô¤¼Æ×ʽð»áÁ¢¼´·µ»¹¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÕâЩÎÞµ£±£´û¿î £¬ £¬£¬£¬£¬ÔÚ²»±ä±ÒÖ®¼ä½øÐÐÌ×Àû¡£¡£¡£¡£¡£Æ¾¾ÝEtherscanµÄÊý¾Ý £¬ £¬£¬£¬£¬ºÚ¿Í×ܹ²´ÓDeFi½è´ûƽ̨Aave½èÓÃÁË80000ÒÔÌ«±Ò¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.coindesk.com/value-defi-suffers-6m-flash-loan-attack


4.°²È«×êÑÐÈËÔ±·¢ÏÖÐÂEmail Appender¿ÉÈÆ¹ýɱ¶¾Èí¼þ


4.png


Gemini Advisory×êÑÐÈËÔ±·¢ÏÖÐÂEmail Appender¿ÉÈÆ¹ýɱ¶¾Èí¼þ £¬ £¬£¬£¬£¬Ð­Öú¸ü¸´ÔÓµÄÍøÂç´¹µöºÍÆóÒµµç×ÓÓʼþй¶£¨BEC£©¹¥»÷¡£¡£¡£¡£¡£Email AppenderÀûÓÃÍ´´¦Ìî³ä £¬ £¬£¬£¬£¬ÔÚ¶àÖÖ·þÎñÉϳÁÓÃÃÜÂë¡£¡£¡£¡£¡£´Ë±í £¬ £¬£¬£¬£¬ÆäʹÓÃÓÐЧµÄ·¢¼þÈ˺ÍÊÕ¼þÈË×Ö¶Î £¬ £¬£¬£¬£¬Äܹ»ÇáËÉÈÆ¹ý·ÀÓù´ëÊ© £¬ £¬£¬£¬£¬ºýŪÊܺ¦ÕßÀ´´«µÝڲƭÐÔÐÂÎźÍÔ̺¬¶ñÒâÈí¼þµÄµç×ÓÓʼþ¡£¡£¡£¡£¡ £¿ £¿ £¿ £¿£¿£¿£¿£¿Éͨ¹ýÆôÓöà³ÁÉí·ÝÑéÖ¤Ö°ÄÜ·À±¸´ËÀ๥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-tool-lets-attackers-easily-create-reply-chain-phishing-emails/


5.˼¿ÆTalosÅû¶ÐÂRAT CRAT»òÓëAPT LazarusÓйØ


5.jpg


˼¿ÆTalosÅû¶RAT CRATCRAT¶ñÒâÈí¼þ¼Ò×åµÄа汾 £¬ £¬£¬£¬£¬»òÓëAPT LazarusÓйء£¡£¡£¡£¡£Õâ´Î·¢ÏÖµÄа汾Ô̺¬¶àÖÖRATÖ°ÄÜ¡¢²å¼þºÍ¶àÖÖ¼ì²âÌӱܼ¼Êõ £¬ £¬£¬£¬£¬ÆäÖ¸±ê £¬ £¬£¬£¬£¬Õ½Êõ¡¢¼¼ÊõºÍ·¨Ê½£¨TTP£©Ò²ÓëLazarusGroupµÄÀàËÆ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ×÷Ϊ¶ÀÁ¢µÄRAT £¬ £¬£¬£¬£¬´ÓÆäC2·þÎñÆ÷ÏÂÔØ²¢¼¤»îÆäËû¶ñÒâ²å¼þ £¬ £¬£¬£¬£¬CiscoTalosÒѾ­·¢ÏÖÁ˶à¸ö²å¼þ £¬ £¬£¬£¬£¬Ô̺¬ÀÕË÷Èí¼þ¡¢ÆÁÄ»²¶»ñ¡¢¼ôÌù°å¼à¶½ºÍ¼üÅ̼ͼÆ÷×é¼þ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/11/crat-and-plugins.html


6.ESETÅû¶LazarusÕë¶Ôº«¹ú¹©¸øÁ´µÄй¥»÷»î¶¯


6.jpg


ESET×êÑÐÈËÔ±Åû¶LazarusÕë¶Ôº«¹ú¹©¸øÁ´µÄй¥»÷»î¶¯¡£¡£¡£¡£¡£½üÄêÀ´ £¬ £¬£¬£¬£¬LazarusÀ©´óÁ˹¥»÷ÁìÓò £¬ £¬£¬£¬£¬²»½öÊÇÇÔÈ¡¹«Ë¾µÄÃô¸ÐÊý¾Ý»¹·ÛËé¼ÓÃÜÇ®±Ò×éÖ¯¡£¡£¡£¡£¡£ESET°µÊ¾ £¬ £¬£¬£¬£¬ÔÚÕâÀ๩¸øÁ´¹¥»÷ÖÐ £¬ £¬£¬£¬£¬ºÚ¿ÍÀûÓÃÁ˺«¹ú»¥ÁªÍøÓû§½Ó¼ûµ±¾Ö»ò½ðÈÚ·þÎñÍøÕ¾Ê±±ØÒª×°Ööî±íµÄ°²È«Èí¼þ¡£¡£¡£¡£¡£Ê×ÏÈÒªÇóÓû§ÏÂÔØWIZVERA VeraPort £¬ £¬£¬£¬£¬¸Ã·¨Ê½ÓÃÓÚÖÎÀí½Ó¼ûÌØ¶¨ÓòËùÐèµÄÈí¼þÏÂÔØ¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»´ÓÒ»¸öºÏ·¨µ«±»Ð¹Â¶µÄÍøÕ¾¸ü»»Õý±¾Òª½»¸¶¸øWIZVERA VeraPortÓû§µÄÈí¼þ £¬ £¬£¬£¬£¬ÒÔ´ËÀ´·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lazarus-malware-strikes-south-korean-supply-chains/